MEDIUM
Mozilla Arbitrary code execution using SJOW and fast native function
Published Jul 30, 2010
6.8
MEDIUMCVSS 2.0
EPSS 1.49%
Description
Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
firefox-0:3.6.7-2.el4
Fixed · RHSA-2010:0547
Red Hat Enterprise Linux 5
firefox-0:3.6.7-2.el5
Fixed · RHSA-2010:0547
Red Hat Enterprise Linux 5
xulrunner-0:1.9.2.7-2.el5
Fixed · RHSA-2010:0547
Red Hat Enterprise Linux 6
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | firefox-0:3.6.7-2.el4 | Fixed | RHSA-2010:0547 |
| Red Hat Enterprise Linux 5 | firefox-0:3.6.7-2.el5 | Fixed | RHSA-2010:0547 |
| Red Hat Enterprise Linux 5 | xulrunner-0:1.9.2.7-2.el5 | Fixed | RHSA-2010:0547 |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://www.mozilla.org/security/announce/2010/mfsa2010-38.html x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-1215 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=567069 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=615463 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1215
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11527 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-1215
| Link | Providers | Tags |
|---|---|---|
| http://www.mozilla.org/security/announce/2010/mfsa2010-38.html | x_refsource_CONFIRMVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2010-1215 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=567069 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=615463 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-1215 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11527 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2010-1215 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 30, 2010
Updated Aug 7, 2024
Reserved Mar 30, 2010
Link CVE-2010-1215
CISA Vulnrichment
Updated n/a